Skip to content

Privacy Policy

Last updated: 25 August 2026

This policy explains what information FinanceFlow processes, why it is processed, and what control you have over it. It applies to the FinanceFlow web application and website.

Who this policy is from

FinanceFlow is operated by the entity responsible for providing the FinanceFlow service, referred to in this policy as “we” or “us”. If you need to reach us about anything in this policy, use the details published on our contact page.

Information we process

The service processes the following, all of it entered or generated through normal use:

  • Account information. Your name, your email address, and a cryptographic hash of your password. We never store your password itself.
  • Business information. The business name, country, default currency, tax details and address you provide when setting up your workspace.
  • Records you create. Customers, vendors, invoices and their line items, income, expenses and payments, together with any notes, references and files you attach.
  • Technical information. Standard server-side records generated when the application runs, such as request and error logs, used to keep the service working.

FinanceFlow does not connect to bank accounts and never asks for banking credentials. It does not carry out automated profiling or automated decision-making about you.

How we use it

  • To provide the service: storing, calculating and displaying the records you create.
  • To sign you in and keep your session secure.
  • To generate documents you ask for, such as invoice PDFs.
  • To keep the service secure and to investigate faults.

We do not sell your information, and we do not use the records in your workspace for advertising.

Information about your own customers

Much of what you enter into FinanceFlow is information about other people and businesses: your customers and vendors. For that information you are the one who decides why and how it is processed, and we process it on your behalf in order to run the service.

You are responsible for making sure you have the right to enter that information, that it is used lawfully, and that the people it relates to receive whatever notice their own local law requires.

Service providers

Running FinanceFlow requires a small number of infrastructure providers. Each receives only what it needs to perform its function:

  • Application hosting. A cloud hosting provider serves the application and processes requests.
  • Database. A managed PostgreSQL database stores the records described above.
  • File storage. Amazon S3 stores files uploaded through the service.
  • Document conversion. Abacus AI converts invoice documents to PDF when you request one. The content of the invoice being converted is sent to that provider for the duration of the conversion.

We do not share your records with other customers of the service. Each business workspace is separated from every other, and requests can only reach the workspace they were authenticated for.

Where information is processed

Our providers operate data centres in more than one country, so your information may be processed outside the country you are in. Where the law that applies to you restricts such transfers, we rely on the safeguards those providers make available for international transfers.

How long we keep it

We keep the records in your workspace for as long as your account is open, because the service exists to hold them. If your account is closed, we keep information only for as long as we need it to meet legal or accounting obligations that apply to us, and then remove it.

We have not set a fixed retention period, and we would rather say so plainly than publish a number we could not stand behind. If you need a specific commitment before adopting the service, ask us and we will confirm what we can offer.

Security

These are the measures actually built into the service:

  • Passwords are stored only as salted cryptographic hashes, never in readable form.
  • Sessions are carried by signed tokens, and requests without a valid one are refused.
  • Every query is scoped to the workspace of the signed-in user, so one business cannot read or change another’s records.
  • Traffic between your browser and the service, and between the service and its database, is encrypted in transit.

We hold no security certifications and make no claim to any. No online service can promise perfect security, and we do not.

Your rights

Data protection law in many countries gives people the right to ask for a copy of their personal information, to have inaccurate information corrected, to have information deleted, to restrict or object to certain processing, and to complain to a supervisory authority. Which of these apply to you depends on where you live.

Whatever your location, you can view and correct most of the information in your workspace directly in the application. For anything you cannot change yourself, contact us and we will respond as quickly as we reasonably can.

Children

FinanceFlow is a tool for businesses and is not directed at children. We do not knowingly create accounts for anyone below the age at which they can enter into a contract where they live.

Changes to this policy

If this policy changes in a way that materially affects you, we will update the date shown at the top of this page and, where it matters, tell you inside the application.